
Insider threats account for 60% of data breaches and cost businesses an average of $15.4 million per year. Now is the time to pay attention, argues Samantha Humphries at Exabeam
September is Insider Threat Awareness Month, which aims to educate individuals and organisations on the dangers of insider threats and how to stop them, no matter what form they take. These threats, posed by legitimate users, can prove more elusive and harder to detect than traditional external threats.
One of the biggest challenges when protecting against insider threats is their unpredictable and quiet nature. When it comes to external threats, with someone trying to breach a well protected endpoint for example, there will be numerous alarms and alerts triggered by security systems.
However, these same security systems rarely turn their attention inward, so businesses could be haemorrhaging data via insider threats for any amount of time without even knowing.
Let’s begin by exploring the most common categories of insider risk:
Regardless of the size of your business, these threats are real, however, there is a range of tools and technologies on the market that can help in the battle against them, from training through to behavioural analytics.
Train your employees from day one
Perhaps the simplest, but also a very effective method: train each employee to mitigate risky behaviour and prevent them from becoming unintentional threats. By educating your workforce about the dangers of phishing attacks and social engineering, they will become a frontline defence against the most common types of threats.
Moreover, training your employees about rogue elements means they can help spot suspicious behaviour among colleagues.
Put behavioural analytics at the heart of your defence
User and Entity Behaviour Analytics (UEBA) is one of the most powerful technologies at our disposal. It first creates a baseline of regular activity – using machine learning – for all systems, employees, and third parties.
For example, office workers typically are operational between 9am and 6pm and spend 90% of their time using Office applications. Once these baselines have been built, deviations can be picked up instantly and automatically flagged as potential security alerts.
So, if an employee in marketing is trying to access sensitive financial data or applications at 2am, your UEBA solution will flag it, enabling your security team to take further action immediately. This goes beyond just automated data collection into a much smarter, observational approach to behavioural analysis.
These alerts, combined with contextual information, ensure you can highlight insider threats much more quickly than using traditional, time-consuming manual analysis and investigation, making it an efficient way of identifying insider threat attacks before major damage is done.
As the battle against malicious behaviour continues to be waged, internal threats will remain at the forefront as one of the most powerful enemies that businesses face.
By taking the lead on simple steps, such as security training, and introducing sophisticated new technological tools, such as UEBA, we can detect threats before they do too much damage, thus keeping data secure and protecting businesses’ reputations.
Samantha Humphries is Head of Security Strategy EMEA at Exabeam.
Main image courtesy of iStockPhoto.com
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543